<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Starting out with Glastopf</title>
	<atom:link href="http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/</link>
	<description>Offensive and Defensive IT Security</description>
	<lastBuildDate>Thu, 02 Feb 2012 15:40:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-901</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Fri, 12 Aug 2011 21:38:35 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-901</guid>
		<description><![CDATA[Andrew, what I&#039;m willing to gain is the same as yours &quot;study malware behavior&quot;. I will Install &amp; configure Kippo+Dionaea then just like you.

Is there any tools you use on top of those? For analysis or monitoring or anything you might find useful to tell me about, I will be appreciated.

Thanks for your reply.]]></description>
		<content:encoded><![CDATA[<p>Andrew, what I&#8217;m willing to gain is the same as yours &#8220;study malware behavior&#8221;. I will Install &amp; configure Kippo+Dionaea then just like you.</p>
<p>Is there any tools you use on top of those? For analysis or monitoring or anything you might find useful to tell me about, I will be appreciated.</p>
<p>Thanks for your reply.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Waite</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-900</link>
		<dc:creator><![CDATA[Andrew Waite]]></dc:creator>
		<pubDate>Fri, 12 Aug 2011 17:54:35 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-900</guid>
		<description><![CDATA[Ultimately depends what you&#039;re hoping to gain from running honeypot sensors. I wouldn&#039;t try to dissuade anyone from using Glastopf or any other system, just that I don&#039;t have enough experience with Glastopf to be any help.

I&#039;ve tried running most honeypot systems I&#039;ve been able to get my hands on, and written about most of my experiences here. Each system had a different tact and provides different information.

I&#039;ve scaled my honeypot farm back recently as I was needing to spend less time in my lab. I now just run Dionaea and Kippo, for the most part they just look after themselves with any problems. Plus both systems are actively developed, so when I do find extra time to play with new toys, I can build in some additional functionality to my existing systems without needing to build and learn new frameworks.

As I said first, technology dependes on exactly what you&#039;re looking to gain from the technology. Just about everyone I know that uses honeypot systems use a different selection and configuration to match their needs.

Sorry if that doesn&#039;t help too much, best advice I can give is to dive into everything see what works best for you.]]></description>
		<content:encoded><![CDATA[<p>Ultimately depends what you&#8217;re hoping to gain from running honeypot sensors. I wouldn&#8217;t try to dissuade anyone from using Glastopf or any other system, just that I don&#8217;t have enough experience with Glastopf to be any help.</p>
<p>I&#8217;ve tried running most honeypot systems I&#8217;ve been able to get my hands on, and written about most of my experiences here. Each system had a different tact and provides different information.</p>
<p>I&#8217;ve scaled my honeypot farm back recently as I was needing to spend less time in my lab. I now just run Dionaea and Kippo, for the most part they just look after themselves with any problems. Plus both systems are actively developed, so when I do find extra time to play with new toys, I can build in some additional functionality to my existing systems without needing to build and learn new frameworks.</p>
<p>As I said first, technology dependes on exactly what you&#8217;re looking to gain from the technology. Just about everyone I know that uses honeypot systems use a different selection and configuration to match their needs.</p>
<p>Sorry if that doesn&#8217;t help too much, best advice I can give is to dive into everything see what works best for you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-899</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Fri, 12 Aug 2011 13:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-899</guid>
		<description><![CDATA[Okay, which Honeypot do you recommend then? Dionaea?

I have Kippo, Dionaea, etc running. Do you suggest I stick with Dionaea? I&#039;m running it from the Mercury-dvd you posted once, but I&#039;m thinking on moving to a clean install of it on a separate system.

Any suggestions would be really helpful to me.]]></description>
		<content:encoded><![CDATA[<p>Okay, which Honeypot do you recommend then? Dionaea?</p>
<p>I have Kippo, Dionaea, etc running. Do you suggest I stick with Dionaea? I&#8217;m running it from the Mercury-dvd you posted once, but I&#8217;m thinking on moving to a clean install of it on a separate system.</p>
<p>Any suggestions would be really helpful to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Waite</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-898</link>
		<dc:creator><![CDATA[Andrew Waite]]></dc:creator>
		<pubDate>Fri, 12 Aug 2011 11:16:30 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-898</guid>
		<description><![CDATA[Afraid I don&#039;t run Glastopf any more so can&#039;t help too much. I ran into several problems and issues whilst setting up, likely similar issues that you&#039;re finding now. As I run my sensors in my own time on top of a long work schedule I found I gained a better ROI from other honeypot systems.

I am still really interested in the Glastopf, and think the information that it&#039;s designed to collect holds a definite interest. If you&#039;re struggling with setup I&#039;d suggest jumping into the glastopf irc channel, I got some great and rapid responses from Lukas and the rest of the channel.]]></description>
		<content:encoded><![CDATA[<p>Afraid I don&#8217;t run Glastopf any more so can&#8217;t help too much. I ran into several problems and issues whilst setting up, likely similar issues that you&#8217;re finding now. As I run my sensors in my own time on top of a long work schedule I found I gained a better ROI from other honeypot systems.</p>
<p>I am still really interested in the Glastopf, and think the information that it&#8217;s designed to collect holds a definite interest. If you&#8217;re struggling with setup I&#8217;d suggest jumping into the glastopf irc channel, I got some great and rapid responses from Lukas and the rest of the channel.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-897</link>
		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Thu, 11 Aug 2011 16:01:21 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-897</guid>
		<description><![CDATA[Hi Andrew,

I&#039;m trying to get glastopf and glastopfng up and running, but some problems in that. Can you share the way you setup the systems?

Regards,]]></description>
		<content:encoded><![CDATA[<p>Hi Andrew,</p>
<p>I&#8217;m trying to get glastopf and glastopfng up and running, but some problems in that. Can you share the way you setup the systems?</p>
<p>Regards,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Glastopf &#8211; First experiences &#171; Diatel</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-412</link>
		<dc:creator><![CDATA[Glastopf &#8211; First experiences &#171; Diatel]]></dc:creator>
		<pubDate>Fri, 28 May 2010 12:26:24 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-412</guid>
		<description><![CDATA[[...] I will keep watching the logs and I will inform you of any interesting attack.  I recommend you to read Andrew Waite&#8217;s post about glastopf. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] I will keep watching the logs and I will inform you of any interesting attack.  I recommend you to read Andrew Waite&#8217;s post about glastopf. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Waite</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-155</link>
		<dc:creator><![CDATA[Andrew Waite]]></dc:creator>
		<pubDate>Wed, 02 Dec 2009 09:25:38 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-155</guid>
		<description><![CDATA[Hi Lukas,

thanks for the comment. I&#039;m guessing I&#039;ve still got something that isn&#039;t quite right in my setup then, getting nowhere close to 1k hits per day. Back to the drawing board to see where I&#039;ve got an issue.....

Andrew]]></description>
		<content:encoded><![CDATA[<p>Hi Lukas,</p>
<p>thanks for the comment. I&#8217;m guessing I&#8217;ve still got something that isn&#8217;t quite right in my setup then, getting nowhere close to 1k hits per day. Back to the drawing board to see where I&#8217;ve got an issue&#8230;..</p>
<p>Andrew</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lukas</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-153</link>
		<dc:creator><![CDATA[Lukas]]></dc:creator>
		<pubDate>Tue, 01 Dec 2009 21:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-153</guid>
		<description><![CDATA[Hey Andrew, thank you for the feedback! How many hits did you get? A standard Glastopf Sensor should get more than 1k hits per day. Currently it should be mainly remote file inclusion attacks.

Greetings,
Lukas]]></description>
		<content:encoded><![CDATA[<p>Hey Andrew, thank you for the feedback! How many hits did you get? A standard Glastopf Sensor should get more than 1k hits per day. Currently it should be mainly remote file inclusion attacks.</p>
<p>Greetings,<br />
Lukas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Waite</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-152</link>
		<dc:creator><![CDATA[Andrew Waite]]></dc:creator>
		<pubDate>Tue, 01 Dec 2009 19:33:42 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-152</guid>
		<description><![CDATA[Trying to clear my to-do list for a quiet holiday period. Not worth the grief from family and friends when I try to finish up a bit of coding in the middle of Christmas dinner ;) Attempting to actually unplug from the matrix for more than a 24hour period this year.]]></description>
		<content:encoded><![CDATA[<p>Trying to clear my to-do list for a quiet holiday period. Not worth the grief from family and friends when I try to finish up a bit of coding in the middle of Christmas dinner <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Attempting to actually unplug from the matrix for more than a 24hour period this year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lvdeijk</title>
		<link>http://blog.infosanity.co.uk/2009/12/01/starting-out-with-glastopf/#comment-151</link>
		<dc:creator><![CDATA[lvdeijk]]></dc:creator>
		<pubDate>Tue, 01 Dec 2009 19:29:17 +0000</pubDate>
		<guid isPermaLink="false">http://infosanity.wordpress.com/?p=389#comment-151</guid>
		<description><![CDATA[As said on a tweet. Man get some R&amp;R :) Good research, well done, but seriously get some rest...;)]]></description>
		<content:encoded><![CDATA[<p>As said on a tweet. Man get some R&amp;R <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Good research, well done, but seriously get some rest&#8230;;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

